The InformationWeek -- Blogs

Microsoft

Topics:   Microsoft

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Open Source Processes Infiltrate VeriSign Business Model


Posted by Larry Greenemeier, Jun 3, 2005 04:01 PM

The open-source mindset is taking firm hold within business environments, even when companies aren’t developing open-source software. A terrific example of this is the application development work VeriSign Inc. is doing using VA Software Corp.’s SourceForge Enterprise Edition to integrate a distributed group of software developers. In addition to helping a business unit within the company, which provides a variety of digital commerce and communication products and services, better organize its development efforts worldwide, the SourceForge Enterprise Edition software suite has become a way for VeriSign to more easily prove compliance with Sarbanes-Oxley and Statement of Auditing Standards (SAS) number 70, Service Organizations, an auditing standard developed by the American Institute of Certified Public Accountants.


VeriSign’s security services business unit has for the past year and a half been using SourceForge Enterprise Edition to manage distributed developer teams, who work much the same way as open-source programmers. Each focuses on a particular software component that’s ultimately assembled into a larger project or, in VeriSign’s case, a product.

Without some form of organization and documentation, such projects are unwieldy to manage, says Kathleen Wilson, director of engineering operations for VeriSign’s security services business unit. “We had a painfully slow development process,” she says, adding, “The techniques of open-source development work in a distributed model within VeriSign. Using SourceForge Enterprise Edition, we can create tasks for people on distributed teams and monitor their progress.”

VeriSign’s security services business unit began using SourceForge Enterprise Edition during the development last year of a unified authentication application. “The timing of the project was good for using SourceForge,” Wilson says. “Since it was a brand new project, it didn’t have customer or existing legacy issues.” This test run for SourceForge involved 60 VeriSign staffers over a nine-month period.

Most application development projects require separate applications for a concurrent version system code repository, bug-tracking system, and build/request tool, as well as several meetings or teleconferences to keep all developers on the same page. “With SourceForge, we basically integrated all the concurrent version system and build/request features,” Wilson says. “We don’t have to have meetings anymore.”

VeriSign’s security services business unit has big plans for the expansion of SourceForge use. The division has 200 users on the system, having added legacy application development projects and development work that’s been outsourced offshore. “Seventy-percent of our business unit’s projects have been migrated to SourceForge,” Wilson says. “The goal is to have them all migrated by the end of the year.”

Security has not been a problem because SourceForge features rules-based access controls that limit the information different programmers can access. This is very important when working with outsourced programmers, Wilson says.

VeriSign’s developers were very comfortable with SourceForge’s concept of a central repository, a layout familiar to programmers working on open-source projects. “Most of our developers are very into the idea of open source and are very familiar with VA Software because of their involvement with open source,” Wilson says.

SourceForge has also proved itself to be a valuable tool for providing compliance with Sarbanes-Oxley and SAS 70. “One thing that used to be very painful to me was tracking down documents,” Wilson says. Auditors generally want to see design documentation, test plans, and marketing requirements because VeriSign provides security and payment services. “With the file systems we used before SourceForge, it was very hard to find out where the information was. Now all of the information is in one system.”

Wilson’s team recently finished integrated its bug-tracking tool into the SourceForge system, a move that will give VeriSign customer support representatives and engineers one place to go to request and make software changes. “Customer support has a knowledgebase they use to answer customer questions,” Wilson says. If the answer isn’t there, they enter a query into the bug-tracking system which can be read and answered by an engineer.

Keep your eyes on this space for other ways in which the open-source development is changing the way businesses operate.

« Intel Mobile Strategy A Winning Combination | Main | FBI IT: Lessons To Live By »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. HPC Joins the Dummy Revolution?
  2. Detecting Scalability Problems With Intel Parallel Universe Portal
  3. Just Say No To SFAQL Parallelism


Join The InformationWeek Group On LinkedIn


                           


  1. Top Resources To Save Big On Cyber Monday
  2. AT&T, T-Mobile, Verizon All Offering Black Friday Sales
  3. Verizon Snags Samsung's Omnia II With WinMo 6.5
  4. Murdoch And Microsoft Redefine Search
  5. Thoughts On The Motorola Droid


  1. Ericsson To Buy Nortel GSM Unit For $70 Million
  2. Government CIOs Must Focus On Results, Not Data Centers
  3. Elastra Cloud Server Preps Apps For Azure, Amazon
  4. Joost Assets Acquired By Adconion
  5. Global CIO: Oracle, Larry Ellison, The EU, And MySQL
  6. Infineon, Nokia Collaborating On LTE Chips

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007